Impact
The vulnerability is in the Installation component of Oracle APEX, enabling a local attacker with host logon to compromise the APEX instance. Successful exploitation allows all data accessible by the application. This weakness arises from inadequate access control during installation and results in a confidentiality breach. The CVSS score of 5.5 reflects a moderate risk, affecting confidentiality 24.1, 24.2 and 26.1 are affected. All installations of these releases are vulnerable, while earlier and later releases are not listed as impacted.
Affected Systems
Oracle APEX installations running the 24.1, 24.2, or 26.1 releases are affected. Any host a low‑privileged user and runs one of these releases is vulnerable, regardless of administrative separation. Versions earlier than 24.1 or later than 26.1 are not listed as impacted.
Risk and Exploitability
The EPSS score is less than 1%, indicating a low probability of exploitation as of this analysis. The vulnerability is not included in CISA's KEV catalog. The CVSS vector shows the requirement of local access (AV:L) and low authentication (PR:L) with no user interaction, meaning a user who can log on to the host running APEX can exploit it without remote assistance. The impact is confined to confidentiality, with no described integrity or availability effects.
OpenCVE Enrichment